CRITICALAdvisoryAug 12, 2026
Action required
Prioritize patching CVE-2026-68820 (afd.sys) on all Windows endpoints. Hunt for exploitation attempts by searching for unexpected afd.sys process interactions, kernel crashes, and lateral movement from standard user accounts to SYSTEM.
Affected products
afd.sysWindows Sockets APIWindows User Profile ServiceWindows Container Isolation FS Filter DriverWindows DNS server
CVE IDs